Gain permission to use the connect protocol as the requested clientId, or assign a new clientId.
When the deployment enforces concurrent clients, a network is limited to 100 TOP-LEVEL clients (clients with no source_client_id, which are the network's peers); ancillary clients are not counted. Over the limit the call answers 200 with error.upgrade_required -- a plan limit, not a hard cap -- and an agent can settle it inline with the x402 round trip below.
Request bodyshow schema
udid. Optional. If this is given, it must currently exist in the network. Omit this to assign a new client id.
udid. Optional. The source client id when creating an ancillary client id.
If this is a new device, sets the device name to the description of the device.
If this is a new device, sets the device spec.
Optional. The device's IANA time zone (e.g. America/Chicago), used only to place the onboarding campaign's emails in the user's local day (08:00-21:00 local); never stored on the client. Every app sends it on each auth-client call; the latest wins.
Optional. The device's BCP 47 locale ("de-DE"). Selects the onboarding campaign's template language, falling back to English. Same rules as time_zone.
Optional. Identity roles assigned to the client at creation, immutable after. Only a network session may set these; when omitted, the session's own roles are inherited. The values have no meaning to the network.
Optional. Identity principal assigned to the client at creation, immutable after. Only a network session may set this; when omitted, the session's own principal is inherited.
Optional. Set if the intended use case of the client is cloud proxy. Note local traffic is not allowed on the cloud proxy. A destination must be set via the SDK.
Optional. Allow only the caller's IP subnet to access the proxy.
Optional. Allow only IPs/subnets in the list to access the proxy. The IPs/subnets are converted to the internal IP subnet width.
Optional. If the client supports ECH, this is not needed, since the HTTP proxy URL will itself be the auth.
Optional. If enabled, a WireGuard configuration will be created for the proxy.
Optional. Whenever the device is created, it will be set up with this initial state. To configure the device beyond the initial state, the SDK ProxyDevice must be used. Note that the SDK ProxyDevice must reconfigure the device each time it receives a change notice.
Optional. Use one of country_code or location
Optional. Use one of country_code or location
udid. Optional.
udid. Optional.
udid. Optional.
udid. Optional.
udid. Optional.
udid. Optional.
udid. Optional.
Marks the location as one of the network's own trusted peers, which egresses under ProvideModeNetwork. It is explicit state: a fixed client id alone does not imply a trusted peer, since it can be a public exit.
Setting this exposes the real source IP to the provider.
Opportunistic post-quantum end-to-end encryption to providers that support it; providers without support fall back to plaintext at this layer.
Optional. The default is "quality"
The minimumum number of items in the windows that must be connected via p2p only. Leave 0 for default behavior.
Inclusive, soft limit. When window_size_max==window_size_min, a special fixed size mode is enabled.
Leave 0 to disable (no hard limit)
Clients per source per stream
Leave 0 to disable
Leave 0 to disable (no limit)
Optional. How the proxy device resolves DNS. DoH urls are queried as RFC 8484 wire format, and each must present an IP-SAN certificate when addressed by IP.
A stand-in destination for the platform's plain DNS configuration while the upgrade mux intercepts UDP/TCP :53. It is not an upstream resolver.
Responses2 statuses · show schema
udid
The following proxy URLs and auths may be used:
| URL | Auth |
|---|---|
| https://.: | no auth needed when the client connects with TLS |
| https://: | use HTTP Proxy-Authorization Basic with access_token as the username (empty pass), or Bearer with access_token as the bearer token |
| http://: | use HTTP Proxy-Authorization Basic with access_token as the username (empty pass), or Bearer with access_token as the bearer token |
| tcp://: | use access_token as the username (empty pass) |
| wg://: | use wg_config.config as the full WireGuard config file content, which contains all the necessary keys |
The proxy url will be valid until the client is removed. However, to keep the device and state in memory, the proxy must receive a message at least once per this interval. The SDK ProxyDevice will automatically send a heartbeat with this many seconds. If the proxy is removed from memmory, the next call to the proxy will create a new device set up to the initial_device_state (if present).
datetime
udid
udid
udid. The instance_id of the proxy device.
The WireGuard config file for this client.
A hard cap or a rate limit was hit.
The network is at its plan's limit for concurrent connected top-level clients. Unlike client_limit_exceeded this is a plan limit, not a hard cap: surface an upgrade prompt. It is the flag the x402 inline-payment round trip keys off.